Lucene search

K
cvelistHackeroneCVELIST:CVE-2022-35252
HistorySep 23, 2022 - 12:00 a.m.

CVE-2022-35252

2022-09-2300:00:00
CWE-20
hackerone
www.cve.org
2

5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.9%

When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "https://github.com/curl/curl",
    "versions": [
      {
        "version": "Fixed in curl 7.85.0",
        "status": "affected"
      }
    ]
  }
]